Detectar vulnerabilidades en Go con gosec
En los laboratorios analizamos el código de una aplicación con SonarCloud, Snyk y Semgrep. En este ejercicio el punto de mira es el mismo código fuente, pero con una herramienta que no usamos en los labs: gosec , el analizador estático estándar del ecosistema de Go, que publica reglas mapeadas a CWE de la OWASP. Para demostrar que la herramienta funciona de verdad, la aplicamos a una aplicación…
A group of engineers examined a piece of software using three different tools – SonarCloud, Snyk, and Semgrep. However, they decided to use gosec, a standard static analyzer in the Go ecosystem, which maps its rules to the Common Weakness Enumeration (CWE) standard of the Open Web Application Security Project (OWASP). They applied gosec to a deliberately flawed application written in Go. The tool found 17 issues, of which five were of high severity.
gosec scans the code for patterns that are known to be dangerous, such as storing credentials or private keys in the source code, using system commands with externally provided file paths, using weak hash algorithms, and constructing SQL queries by concatenating strings. Each rule has a unique identifier, a severity level, and an associated CWE. The results can be mapped to compliance requirements.
To run gosec, you need to install the Go compiler. If it's not installed, gosec will terminate without errors and report "Files: 0," giving the impression of a clean scan when it has not analyzed any code. The sample application is a small web server with six routes, each containing a deliberate flaw.
Five of the 17 findings are of high severity, while 11 are medium severity and one is low severity, making a total of 17 issues. The taint analysis rules (G702, G703, G705, and G710) provide more valuable insights than keyword-based rules. These rules follow the value of data as it flows through the function and identifies issues, such as executable commands constructed with user-provided data or insecure cryptographic primitives like MD5 and SHA1.
The authors emphasize that integration of gosec into automated pipelines is crucial. The "-no-fail" flag allows the scan to complete and display the full report, while "-severity = HIGH" failures can be triggered based on high-severity findings. A "#nosec G304" directive can be used to justify exceptions in the code. However, every #nosec should be carefully considered and justified in the code.
The tool can help detect false negatives, such as incorrect business logic without any known dangerous patterns, vulnerabilities in dependencies, and automatically generated code. However, it only supports Go, and a clean report does not guarantee the correctness of the code. It merely indicates that gosec did not find any issues. The difference between these two statements highlights the importance of relying on gosec for a comprehensive analysis rather than just relying on the absence of errors.
Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.